CVE-2017-16572: Incorrect Type Cast
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within FormCalc's closeDoc method. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this to execute code in the context of the current process. Was ZDI-CAN-5073.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16572?
CVE-2017-16572 is classified as a critical severity vulnerability due to its potential for remote code execution.
Who is affected by CVE-2017-16572?
CVE-2017-16572 affects users of Foxit Reader version 8.3.1.21155.
How do I fix CVE-2017-16572?
To fix CVE-2017-16572, users should update their Foxit Reader software to the latest version.
What type of attack does CVE-2017-16572 involve?
CVE-2017-16572 involves a remote code execution attack that requires user interaction to be successful.
What is the impact of exploiting CVE-2017-16572?
Exploiting CVE-2017-16572 allows attackers to execute arbitrary code on the affected system, potentially leading to full system compromise.